Ġewwa network ta' microservices ma tistax tiddependi fuq in-network biss għax hu "intern". Zero-trust jassumi li n-network huwa ostili, għalhekk kull sejħa hija awtentifikata u awtorizzata, u t-traffiku huwa encrypted b'mTLS.
Mutual TLS (mTLS)
Billi differenti minn TLS normali, iż-żewġ naħat jippreżentaw ċertifikati. Kull servizz jipprova l-identità tiegħu, u t-traffiku huwa encrypted fit-transit.
Service A ──cert──▶ Service B
Service A ◀─cert── Service B (both verify each other's identity)
→ caller is authenticated AND data is encrypted
